Deploy Defender on managed macOS and Windows devices
Deploy Defender to managed macOS and Windows devices with organization onboarding, MDM installation, pilot validation, fleet operations, and removal.
- Admin onboardingCreate the organization and installer
- IT distributionDeploy with your device management system
- Pilot firstValidate activity sync before fleet rollout
Then verify sync.
For Cortex organization admins and IT teams deploying Defender to managed macOS and Windows devices. This guide covers organization onboarding, MDM distribution, pilot validation, fleet operations, and removal. To choose a different operating context, see Choose a Cortex deployment. Employees use Set up Defender after the endpoint application appears on their managed device.
JamfmacOS distribution
Microsoft IntuneWindows distribution
Who owns each step
| Owner | Responsibility |
|---|---|
| Chaos Labs | Create the organization and designate the initial admin with your team |
| Organization admin | Complete organization onboarding, download installers, and coordinate Cortex access |
| IT or device admin | Deploy Cortex Defender and manage device, keychain, network, process, and operating-system policies |
| Employee | Sign in, enable approved capture surfaces, and verify activity |
| Developer | Resolve conflicts between local services and Cortex ports |
One person may fill both admin and IT roles. Cortex roles do not grant operating-system or MDM access.
Before deployment
Chaos Labs creates your organization and designates an initial admin; organization creation is not self-service.
Confirm that the organization has completed any required employee notice or consent process for monitored AI activity. Contact the Chaos Labs team if the organization needs a description of what Cortex captures.
Get the installer
Sign in as the designated admin
- Go to cortex.chaoslabs.xyz.
- Sign in with the account designated during organization creation.
- Complete organization onboarding.
- Confirm the organization and identity settings before distributing Cortex Defender.
If the designated admin cannot access the organization, contact the Chaos Labs team before distributing a package or creating another organization.
Obtain the deployment package
The onboarding flow provides the installer for each operating system:
| Platform | Requirement | Package | Tested deployment method |
|---|---|---|---|
| macOS | Apple Silicon and macOS 12 or later | .pkg | Jamf |
| Windows | Windows 10 or 11 on x64 | .exe | Microsoft Intune |
The installers are signed; the macOS package is also notarized. Pilot any deployment method not listed above before rollout.
Distribute the installer provided during organization onboarding. Cortex does not have a public download page.
Compare the download's SHA-256 checksum with the installer dialog before distributing it:
- macOS:
shasum -a 256 Cortex.pkg - Windows:
Get-FileHash Cortex.exe -Algorithm SHA256
If the checksum does not match exactly, discard the download and download it again.
Distribute with MDM
Deployment steps depend on your MDM:
- Add the Cortex
.pkgor.exeto the MDM. - Assign it to a pilot group of representative devices.
- Apply the operating-system, keychain, routing, certificate, and network policies required for the capture paths in your rollout.
- Confirm Cortex Defender installs and opens without requiring the employee to run a separate installer.
- Restart the device after installation when practical. A restart is not normally required, but it can activate newly installed capture services and application settings.
- Provide employees with the organization domain and Set up Cortex Defender.
Cortex Defender can be installed on the macOS and Windows versions listed above. Capture-path availability differs by platform. Use Supported AI tools to choose what to test. Some browsers, desktop apps, command-line tools, and MCP hosts must restart after installation or configuration.
Validate a pilot device
Use at least one representative managed device for each target platform:
- Confirm MDM installed Cortex Defender and an employee can open it.
- Complete Set up Cortex Defender, including verification of every source in the rollout.
- Confirm the synced activity appears for an authorized Cortex user.
- Restart any applications named by Cortex, then confirm their capture paths become active.
- Quit and restart Cortex Defender, then verify capture and sync recover.
Expand the rollout only after these checks pass. Installation and Running status alone do not prove capture works.
Enrollment issues
If Cortex finds no identity providers, confirm that the employee entered the correct organization domain. The organization admin should verify the identity settings.
If sign-in does not complete, send the organization domain, identity provider, work account, and approximate attempt time to the Chaos Labs team.
Managed-device issues
Browser capture may require permission to change routing or certificate trust. Organization Admin access cannot override keychain, certificate-store, endpoint-security, or device-management policy.
If a Defender error names a local port or process, include those details when contacting the Chaos Labs team. Developers running local services can use Fix Cortex Defender port conflicts.
Rollout and fleet operations
Fleet is limited to organization admins. Use it to:
- Filter endpoints by All endpoints, Capturing, No recent capture, Inactive, Unknown, or Needs attention.
- Check Last contact and Last captured for stale endpoints, then inspect Diagnostics and State for supporting evidence and the current verdict.
- Select Get installer to reopen the organization installer flow.
- Refresh the view after a deployment or repair.
Enrollment and revocation happen outside Fleet. Contact the Chaos Labs team for revocation or other device-lifecycle actions that are not available in Cortex.
Offboard or replace a device
For organization offboarding or service termination:
- Export your organization's Cortex data during the service term or within 30 days after termination.
- Resolve any unsynced local backlog before removing Cortex Defender.
- On each device, open Connections → Browser settings.
- Turn off Web routing and Certificate trust to remove browser routing and certificate trust.
- Turn Defender off from Home and wait for Direct connection confirmed.
- Remove Cortex Defender through MDM or the approved device-management path.
Quitting the app is not a substitute for disconnecting it. Confirm direct connections and remove certificate trust before uninstalling.
After the 30-day export window, Cortex data may be irretrievably erased.
See Pause and stop capture for capture controls.
Contact the Chaos Labs team before removing a device that has an unsynced backlog or cannot be disconnected normally.